Microsoft SharePoint Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated and possess the permissions for page creation to be able to exploit this vulnerability.
According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H), integrity (I:H), and availability (A:H). What does that mean for this vulnerability? An attacker who successfully exploits this vulnerability could perform a remote attack that could enable access to the victim's information and the ability to alter information. Successful exploitation could also potentially cause downtime for the targeted environment.
There are multiple update packages available for some of the affected software. Do I need to install all the updates listed in the Security Updates table for the software? Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.
🎯 Affected products2
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002436 (Security Update) — fixed build 16.0.10401.20025 KB5002422 (Security Update) — fixed build 16.0.10401.20025 KB5002437 (Security Update) — fixed build 16.0.16130.20684
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36892
- patchhttps://www.microsoft.com/download/details.aspx?familyid=838d6c3a-7b03-4b62-ab88-9a0a0e0f33c7
- referencehttps://support.microsoft.com/help/5002436
- patchhttps://www.microsoft.com/download/details.aspx?familyid=5f8d695d-b900-4cb2-ad5a-361fce88ac7d
- referencehttps://support.microsoft.com/help/5002422
- patchhttps://www.microsoft.com/download/details.aspx?familyid=66ec07ac-124a-4983-9710-9bf71c5b2adb
- referencehttps://support.microsoft.com/help/5002437